Oval Definition:oval:com.redhat.rhsa:def:20100543
Revision Date:2010-07-20Version:638
Title:RHSA-2010:0543: openldap security update (Moderate)
Description:OpenLDAP is an open source suite of LDAP (Lightweight Directory Access Protocol) applications and development tools.

  • An uninitialized pointer use flaw was discovered in the way the slapd daemon handled modify relative distinguished name (modrdn) requests. An authenticated user with privileges to perform modrdn operations could use this flaw to crash the slapd daemon via specially-crafted modrdn requests. (CVE-2010-0211)

    Red Hat would like to thank CERT-FI for responsibly reporting the CVE-2010-0211 flaw, who credit Ilkka Mattila and Tuomas Salomäki for the discovery of the issue.

  • A flaw was found in the way OpenLDAP handled NUL characters in the CommonName field of X.509 certificates. An attacker able to get a carefully-crafted certificate signed by a trusted Certificate Authority could trick applications using OpenLDAP libraries into accepting it by mistake, allowing the attacker to perform a man-in-the-middle attack. (CVE-2009-3767)

    Users of OpenLDAP should upgrade to these updated packages, which contain backported patches to resolve these issues. After installing this update, the OpenLDAP daemons will be restarted automatically.
  • Family:unixClass:patch
    Status:Reference(s):CVE-2009-3767
    CVE-2010-0211
    RHSA-2010:0543
    RHSA-2010:0543-01
    RHSA-2010:0543-01
    Platform(s):Red Hat Enterprise Linux 4
    Product(s):
    Definition Synopsis
  • Red Hat Enterprise Linux must be installed
  • OR Package Information
  • Red Hat Enterprise Linux 4 is installed
  • AND
  • compat-openldap is earlier than 0:2.1.30-12.el4_8.3
  • AND compat-openldap is signed with Red Hat redhatrelease2 key
  • openldap is earlier than 0:2.2.13-12.el4_8.3
  • AND openldap is signed with Red Hat redhatrelease2 key
  • openldap-clients is earlier than 0:2.2.13-12.el4_8.3
  • AND openldap-clients is signed with Red Hat redhatrelease2 key
  • openldap-devel is earlier than 0:2.2.13-12.el4_8.3
  • AND openldap-devel is signed with Red Hat redhatrelease2 key
  • openldap-servers is earlier than 0:2.2.13-12.el4_8.3
  • AND openldap-servers is signed with Red Hat redhatrelease2 key
  • openldap-servers-sql is earlier than 0:2.2.13-12.el4_8.3
  • AND openldap-servers-sql is signed with Red Hat redhatrelease2 key
  • BACK